ADR 0194: the no-copies check allows each node's loopback stub
This commit is contained in:
@@ -358,10 +358,10 @@ seat of capacity one, placed on the node every tunnel converges on. It holds one
|
||||
`<node>.internal` and everything under it — and listens on the private network only. Every node's
|
||||
`node-resolver-config` routes the mesh's suffix to it and leaves every other name with public
|
||||
resolvers; plain `resolv.conf` cannot route by domain, so the asking side is a stub that can — a
|
||||
`systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the suffix
|
||||
to `mesh-resolver`. The container runtime
|
||||
cannot use a loopback stub, so its `dns` names `mesh-resolver`, which forwards public names for
|
||||
containers — the one place a public name passes through the mesh
|
||||
`systemd-resolved` module claiming `node-resolver-config` in place of `resolv-conf`, routing the
|
||||
suffix to `mesh-resolver`. The container runtime cannot use a loopback stub, so its `dns` names
|
||||
`mesh-resolver`, which forwards public names for containers — the one place a public name passes
|
||||
through the mesh
|
||||
([ADR 0194](../../02-DECISIONS/0194-the-mesh-has-one-resolver-and-every-node-asks-it-for-the-meshs-names.md)).
|
||||
|
||||
**No node holds a copy.** The per-node resolver, its zones file and the mesh's region of `/etc/hosts`
|
||||
@@ -369,7 +369,7 @@ go: every resolution fault found on 2026-10-03 was a copy disagreeing with the t
|
||||
read once at start, an operator's old line beside the mesh's, a node's resolver lent to a LAN. No
|
||||
member's resolver answers a LAN; a router pointing at one is moved first. *Checked by `resolvectl` on
|
||||
each node (the tunnel's link, `mesh-resolver`, the suffix as routing domain), by no node but the
|
||||
holder listening on port 53, and by the router's DHCP DNS option naming no node.*
|
||||
holder answering DNS on a private or LAN address, and by the router's DHCP DNS option naming no node.*
|
||||
|
||||
*What follows describes the per-node resolver this replaces — how it was built and why the roles were
|
||||
split. The split stands; the serving role's scope is what moved.*
|
||||
|
||||
Reference in New Issue
Block a user